POST
/v1/organizations/{organizationId}/first-identityProvision an Organization's first authenticated caller
Create the first Organization-scoped ServicePrincipal, Admin Grant, and API key, returning the key exactly once. This operation is for Cantora operators.
Cantora-operated endpoint
Authentication
Send an API key as a Bearer token in the Authorization header.
Parameters
Responses
201OrganizationIdentityProvisionedapplication/json401Unauthorizedapplication/json403Forbiddenapplication/json404NotFoundapplication/json409Conflictapplication/jsonReusable schemas
OrganizationIdentityProvisionedJsonEncoding
object- unknown properties allowed
false
organizationIdrequiredstringThe Organization identifier.All of- maximum length
64
A Cantora Organization identifier, prefixed with `org_`.- pattern
^org_[\s\S]+$
- maximum length
principalIdrequiredstringThe Principal identifier.All of- maximum length
64
A Cantora Principal identifier, prefixed with `principal_`.- pattern
^principal_[\s\S]+$
- maximum length
grantIdrequiredstringThe identifier of the Grant issued with the identity.All of- maximum length
64
A Cantora Grant identifier, prefixed with `grant_`.- pattern
^grant_[\s\S]+$
- maximum length
rolerequiredstringThe Organization role granted to the provisioned identity.- allowed values
"admin"
- allowed values
apiKeyIdrequiredstringThe identifier of the issued API key.All of- maximum length
64
A Cantora API key identifier, prefixed with `apikey_`.- pattern
^apikey_[\s\S]+$
- maximum length
apiKeyrequiredstringThe Organization's initial provisioning credential, returned exactly onceexpiresAtrequiredstringWhen the issued API key expires, in UTC.- format
date-time
- format
UnauthorizedJsonEncoding
object- unknown properties allowed
false
_tagrequiredstringThe stable machine-readable error type.- allowed values
"Unauthorized"
- allowed values
reasonrequiredstringA safe explanation of why the credential was rejected.
ForbiddenJsonEncoding
object- unknown properties allowed
false
_tagrequiredstringThe stable machine-readable error type.- allowed values
"Forbidden"
- allowed values
permissionrequiredstringThe permission required by the refused operation.
NotFoundJsonEncoding
object- unknown properties allowed
false
_tagrequiredstringThe stable machine-readable error type.- allowed values
"NotFound"
- allowed values
resourcerequiredstringThe resource type relevant to the error.idrequiredstringThe identifier supplied for the resource that was not found.
ConflictJsonEncoding
object- unknown properties allowed
false
_tagrequiredstringThe stable machine-readable error type.- allowed values
"Conflict"
- allowed values
resourcerequiredstringThe resource type relevant to the error.reasonrequiredstringA safe explanation of the state conflict.